Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?

⚠ Common exam trap

CC often tests the overlap between integrity and non-repudiation for digital signatures, tempting candidates to choose non-repudiation even though the question asks specifically about the CIA triad.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Integrity

Digital signatures use cryptographic hashing and asymmetric encryption to verify that data has not been altered in transit or at rest, which directly addresses the Integrity pillar of the CIA triad. If even a single bit of the software update changes, the signature verification fails, proving tampering. While signatures also provide authentication and non-repudiation, the question specifically asks which CIA triad aspect is primarily addressed, and integrity is the correct mapping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Availability

    Why it's wrong here

    Digital signatures verify integrity and origin, not uptime or service reachability, so availability is untouched by signature verification. Availability controls — redundancy, backups, DDoS mitigation — would be the answer if the requirement were ensuring the update remains accessible to all endpoints during rollout.

  • ✗

    Confidentiality

    Why it's wrong here

    Signatures leave the update readable by anyone; they prove integrity and signer identity, not secrecy. Confidentiality would be the answer if the update contents had to be hidden from unauthorised parties, which calls for encryption rather than signing.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation is a by-product of signing, but the scenario's stated goal — detecting alteration in transit — is integrity, the property signatures directly assert. Non-repudiation would be the answer if the requirement were preventing the signer from later denying authorship of the update.

  • ✓

    Integrity

    Why this is correct

    Digital signatures use asymmetric cryptography to verify that software updates remain unaltered, detecting any modification between publisher and recipient. This directly addresses integrity, the CIA component concerned with data remaining accurate and trustworthy, rather than confidentiality or availability.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.